CVE-2026-6807Disclosure

HIGHCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 11 signals
  • Disclosure: 6 classified signals
  • Peaked 3d ago at 3 mentions (2026-04-29); latest day: 3
  • 11 total mentions across 5 days

Deep dive

Activity timeline11 mentions / 5d
01223Mentions · 2026-04-28: 2Mentions · 2026-04-29: 3Mentions · 2026-04-30: 1Mentions · 2026-05-27: 2Mentions · 2026-05-28: 3PoC Mentioned / Linked · 2026-04-29: 2Exploit Tool / Code · 2026-04-29: 1Active Exploitation · 2026-05-28: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-28: 2Technical Details · 2026-04-29: 3Technical Details · 2026-04-30: 1Technical Details · 2026-05-27: 2Technical Details · 2026-05-28: 304-2804-2904-3005-2705-28
Signal classification5 categories
Disclosure
654.5%
PoC
218.2%
Patch
19.1%
Active Exploitation
19.1%
General
19.1%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-282
Disclosure2
2026-04-293
Disclosure1PoC2
2026-04-301
Patch1
2026-05-272
Disclosure2
2026-05-283
Active Exploitation1Disclosure1General1
Full discourse11 posts
  • Nicolas Krassas@Dinosn
    PoC

    Functional POC for Grassmarlin CVE 2026-6807 https://github.com/SecTestAnnaQuinn/Grassmarlin-CVE-2026-6807-XXE-POC/tree/main

    Post summary

    A functional PoC and GitHub repository for the CVE-2026-6807 XXE vulnerability in Grassmarlin have been released.

    00030847
    158.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR The NSA's retired GrassMarlin OT network analysis tool—once a cornerstone of industrial control system defense—now leaks sensitive ICS/SCADA discovery data via an unpatched XML External Entity (XXE) vulnerability (CVE-2026-6807, CVSS 5.5). CISA issued ICS Advisory…

    Post summary

    The NSA’s retired GrassMarlin OT network analysis tool is being actively abused in the wild through an unpatched XML External Entity vulnerability, leaking sensitive SCADA discovery data.

    10000118
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Tool That Was Meant to Protect Became the Weapon: GrassMarlin XXE Data Theft (CVE-2026-6807) On April 29, 2026, CISA flagged CVE-2026-6807, an XXE vulnerability in GrassMarlin, the now-archived open-source OT network visualization and analysis tool originally…

    Post summary

    The article reports CISA’s flagging of CVE‑2026‑6807, an XXE vulnerability in the GrassMarlin tool that could lead to data theft. No exploitation details, patches, or PoC references are provided.

    1000033
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-6807 · 5.5 The Tool That Was Meant to Protect Became the Weapon: GrassMarlin XXE Data Theft (CVE-2026-6807)

    Post summary

    The snippet references CVE-2026-6807, highlighting an XXE-based data theft flaw in GrassMarlin, but provides no details on exploitation or patches.

    1000036
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR CISA issued ICS Advisory ICSA-26-118-01 for CVE-2026-6807, a critical XML External Entity (XXE) vulnerability in GrassMarlin, an OT network analysis tool developed and open-sourced by the NSA. The tool reached end-of-life in 2017 with no vendor patch forthcoming. A…

    Post summary

    The CISA advisory announces a critical XXE vulnerability (CVE‑2026‑6807) in the obsolete NSA tool GrassMarlin, noting the lack of a vendor patch.

    10000144
    227 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-6807 · 5.5 The Tool That Cannot Be Fixed: GrassMarlin XXE Exposes NSA's Archived OT Security Weapon to Data Theft

    Post summary

    The snippet announces CVE-2026-6807, an XXE vulnerability in GrassMarlin, highlighting its potential to expose NSA’s archived OT security weapon to data theft, without providing proof‑of‑concept details, exploitation tools, or patches.

    1000036
    227 followersView on X
  • ThreatCluster@threatcluster
    PoC

    BREAKING: CISA warns CVE-2026-6807 in NSA GrassMarlin tool enables XXE data theft in all versions, with public PoC and no patches as the product went EOL in 2017. https://threatcluster.io/cluster/cisa-warns-of-data-theft-vulnerability-in-nsas-grassmarlin-t-c7657dd4

    Post summary

    CISA has issued a warning about CVE-2026-6807, an XXE data‑theft flaw in NSA GrassMarlin with a public PoC available, but no patch exists because the product is EOL.

    0001052
    170 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-6807: NSA GRASSMARLIN XXE Vulnerability — Detection and Hardening Guide "CISA flags NSA GRASSMARLIN (CVE-2026-6807) for…" 🔍 Full article at http://securityarsenal.com — search the title #CyberSecurity #ThreatIntel #mdr #threathunting #endpointdetection

    Post summary

    The text announces CISA’s flagging of CVE-2026-6807 (NSA GRASSMARLIN XXE) and supplies a detection and hardening guide, providing mitigation steps but no exploit or patch details.

    0000025
    14 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Disclosure

    TRC analysis shows attackers can exploit CVE-2026-6807 in NSA GRASSMARLIN to access sensitive files through XXE injection. The discontinued ICS mapping tool enables credential extraction and potential lateral movement within industrial networks. Runtime segmentation helps contain post-compromise activity in critical infrastructure. 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/nsa-grassmarlin-cve-2026-6807-xxe-vulnerability #ICS #CloudSecurity

    Post summary

    Researchers disclose an XXE vulnerability (CVE-2026-6807) in NSA GRASSMARLIN that could enable attackers to read sensitive files via injected XML.

    0000041
    1.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6807 XML Parsing Vulnerability in GRASSMARLIN v3.2.1 Causes Information Disclosure https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6807

    Post summary

    The snippet announces CVE-2026-6807, an XML parsing flaw in Grassmarlin v3.2.1 that can lead to information disclosure, without mentioning PoC, exploitation, or patches.

    0000033
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6807 A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive info… https://www.cve.org/CVERecord?id=CVE-2026-6807

    Post summary

    The text announces CVE-2026-6807, describing an XML input handling flaw in GRASSMARLIN v3.2.1 that could expose sensitive information, but provides no PoC, exploit, or mitigation details.

    0000096
    57.3K followersView on X

Explore more